Infrastructure Security Architect (Contract – Outside IR35)
- Clearance: Active DV + Active NPPV3 (both required)
- Job Title: Infrastructure Security Architect
- Contract: Outside IR35
- Location: UK (hybrid/remote depending on site access)
- Start: ASAP (subject to clearance verification)
- Rate: Competitive (DOE)
Overview:
We are looking for a highly experienced Security Architect with a strong Infrastructure Architecture background to support the design, assurance and delivery of secure platforms in a high-assurance environment. This role suits someone who can operate across enterprise infrastructure, networks, hosting platforms, identity, endpoint, and cloud, producing clear architecture artefacts and driving security-by-design through engineering teams.
You will be working across complex estates (legacy + modern) and supporting secure transformation, ensuring infrastructure designs align to relevant UK security standards and governance.
Key Responsibilities (Security + Infrastructure Architecture):
- Own and deliver security architecture for infrastructure solutions covering:
- Data centres / hosting platforms, virtualisation, storage, backup, DR, and platform services
- Network architecture (segmentation, routing, firewalls, proxies, secure remote access)
- Identity & access architecture (AD, Azure AD/Entra ID, federation, PAM)
- Endpoint / server hardening (Windows/Linux baselines, configuration management, patching)
- Cloud and hybrid connectivity and security patterns (where applicable)
- Produce high-quality architecture documentation, including:
- HLD/LLD, security design packs, reference architectures, patterns/standards, and roadmaps
- Security requirements, control mappings, and architecture decision records
- Lead threat modelling and risk assessments on infrastructure designs; define mitigations and proportionate controls.
- Drive secure-by-design outcomes: work with infrastructure engineers, network teams, platform teams and vendors to implement secure architectures.
- Provide assurance through governance forums (design authorities / architecture review boards), ensuring designs are supportable, compliant, and operationally viable.
- Define and assure controls for:
- Network segmentation / zero trust principles
- Encryption in transit/at rest, key management, certificate services/PKI
- Secure administration models (jump hosts/bastions, privileged access workflows)
- Logging/monitoring/SIEM integration and security observability
- Support operational security posture: contribute to hardening standards, vulnerability management approaches, secure build pipelines, and incident learnings.
Essential Skills & Experience:
- Demonstrable experience as a Security Architect with deep Infrastructure Architecture capability.
- Comfortable producing “client-ready” architecture artefacts and presenting them to senior technical and non-technical stakeholders.
- Strong knowledge of UK security frameworks and standards such as:
- NCSC guidance, HMG Security Policy Framework (SPF), secure architecture principles
- ISO 27001/27002, NIST, CIS (where appropriate)
- Strong grasp of security controls and how they apply to infrastructure (network, compute, identity, endpoint).
- Ability to balance security, operability, performance and cost in design decisions.
Desirable:
- Experience supporting assurance/accreditation style activity (e.g., control mapping, risk treatment approaches).
- Knowledge of DevSecOps / secure automation (IaC concepts, CI/CD security controls).
- Prior work in highly sensitive environments with strict governance, auditability, and separation-of-duties requirements.